Singapore CSA, the Cyber Security Agency of Singapore, warned on 28 August that CVE-2026-55040 and CVE-2026-63520 in Microsoft SharePoint Server were under active exploitation, scored them 9.1 and 8.1, and told organisations to patch immediately 1. SharePoint Server is the on-premises version of Microsoft's document and collaboration platform: the intranet, the document library and the departmental file store, usually holding whatever a company has decided is too sensitive to put anywhere else.
A cloud tenancy is patched by the vendor whether the customer notices or not, while a SharePoint farm is patched by whoever owns it, on a change schedule, with the business signing off the outage. That gap between the two deployment models is why the same product keeps returning to exploitation lists long after a fix exists.
Microsoft's collaboration platform has been a standing item on this beat, with two deserialisation flaws in the same product reaching the US federal exploited-vulnerability catalogue in a single week in July . Four separate SharePoint entries across two months is a pattern rather than an incident, and the attacker interest is not hard to explain: one farm holds thousands of documents that were never meant to leave the building.
The exploitation claim here is Singapore CSA's own, stated in its own alert rather than relayed from a vendor. An administrator weighing an emergency change window has that assessment and Microsoft's patch to work from, which is a firmer footing than a scoring number on its own.
